28 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Present
max-age=15768000
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Excellent
DENY
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Increase HSTS max-age to at least 1 year and add includeSubDomains
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Content-Type-Options: nosniff
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

3 headers
Connection
Performance
Transfer-Encoding
Transfer-Encoding
Performance
chunked
Vary
Performance
Accept-Encoding, User-Agent

Caching Headers

1 headers
Cache-Control
Caching
private, max-age=0, no-cache, no-store, must-revalidate

Content Headers

1 headers
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server
Groupon

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
bm_sz=F86A4D4A8746EFCBD07F59606EE7D0F8~YAAQips+F9K7qRScAQAA5svdLR49h1Se5mrLana+8GRI8/3x9rpkib3eBUmHIn+KqA9U1pEbjU+kgDzLOMbLiGikQg+dFRAH3MvVI7JBHIUziy4AyAQBVpMujkoOTXHY4YqH+eQw1zQe0aPQIuuQiLDGZiLGCPiVxg8MCbuxCFwdb2k0aQyKeardC0iW9IJ1RhKOsktcKTPp74/iXY2RGm7YJmGf+aik9PgU7hDMGtAg3SpkpIN8QvKZjsPrzUbNT1FsXU8B4uIJ96M9iJdjjivDLP8Ry1D/5nZhKE6nKSmu5nivSmK7pt2E8zSPTua7Tgs96Nko7ctxDT3RNUoiKBBvF5DmdzmBijQf1C3usg==~4469040~3223874; Domain=.groupon.com; Path=/; Expires=Thu, 05 Feb 2026 16:53:55 GMT; Max-Age=14399

Other Headers

19 headers
Date
Other
Thu, 05 Feb 2026 12:53:56 GMT
Server-Timing
Other
rReq;dur=646, rCon;dur=0, rHdr;dur=646, hbi;dur=629
X-Akamai-Transformed
Other
0 - 0 -
X-Application
Other
Pull-Itier
X-B-Cookie
Other
0a92cca6-0fe2-4097-92cc-a60fe280973c
X-B3-Traceid
Other
c223ebf9f1624f62970e4fe8ec1253d3
X-Destination
Other
tls_conveyor_pull_itier
X-Envoy-Upstream-Service-Time
Other
646
X-External-Request-Id
Other
true
X-Forwarded-Proto
Other
https
X-Mtls-Upstream-Time
Other
629
X-Original-Request-Id
Other
c223ebf9-f162-4f62-970e-4fe8ec1253d3
X-Page-Id
Other
285d435d-065d-4b71-9d43-5d065d0b7178-1770296035609-TH0
X-Request-Id
Other
c223ebf9-f162-4f62-970e-4fe8ec1253d3,c223ebf9-f162-4f62-970e-4fe8ec1253d3
X-Request-Originated-From
Other
envoy-tls-side-car--ingress-https
X-Response-Served-From
Other
routing-service--public--us-central1--default--conveyor-gcp-production2
X-S-Cookie
Other
285d435d-065d-4b71-9d43-5d065d0b7178
X-Signifyd-Cookie
Other
73e22e6f-4db9-45d7-a22e-6f4db9a5d78f
X-Ua-Compatible
Other
IE=edge,chrome=1

Recommendations

Enable compression (gzip/brotli) to improve performance